266511
|
- |
|
mambo
|
mostlyce
|
PHP remote file inclusion vulnerability in htmltemplate.php in the Chad Auld MOStlyContent Editor (MOStlyCE) as created on May 2006, a component for Mambo 4.5.4, allows remote attackers to execute ar…
|
CWE-94
Code Injection
|
CVE-2006-7104
|
2017-07-29 10:29 |
2007-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266512
|
- |
|
drupal
|
imce_module
|
Unrestricted file upload vulnerability in IMCE before 1.6, a Drupal module, allows remote authenticated users to upload arbitrary PHP code via a filename with a double extension such as .php.gif.
|
NVD-CWE-Other
|
CVE-2006-7109
|
2017-07-29 10:29 |
2007-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266513
|
- |
|
drupal
|
imce_module
|
Directory traversal vulnerability in the delete function in IMCE before 1.6, a Drupal module, allows remote authenticated users to delete arbitrary files via ".." sequences.
|
NVD-CWE-Other
|
CVE-2006-7110
|
2017-07-29 10:29 |
2007-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266514
|
- |
|
futomis_cgi_cafe
|
kmail_cgi
|
Unspecified vulnerability in Futomi's CGI Cafe KMail CGI 1.0.3 and earlier allows remote attackers to bypass authentication and obtain unauthorized email access via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2006-7111
|
2017-07-29 10:29 |
2007-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266515
|
- |
|
planerd.net
|
p-news
|
Unrestricted file upload vulnerability in P-News 2.0 allows remote attackers to upload and execute arbitrary files via an avatar file. NOTE: the provenance of this information is unknown; the details…
|
CWE-20
Improper Input Validation
|
CVE-2006-7113
|
2017-07-29 10:29 |
2007-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266516
|
- |
|
planerd.net
|
p-news
|
P-News 2.0 stores db/user.txt under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and password hashes via a d…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-7114
|
2017-07-29 10:29 |
2007-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266517
|
- |
|
linksys
|
spa921
|
The HTTP server in Linksys SPA-921 VoIP Desktop Phone allows remote attackers to cause a denial of service (reboot) via (1) a long URL, or a long (2) username or (3) password during Basic Authenticat…
|
NVD-CWE-Other
|
CVE-2006-7121
|
2017-07-29 10:29 |
2007-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266518
|
- |
|
noah_spurrier
|
upload_tool_for_php
|
Unrestricted file upload vulnerability in main_user.php in Upload Tool for PHP 1.0 allows remote attackers to upload and execute arbitrary files with executable extensions such as .php. NOTE: the pr…
|
NVD-CWE-Other
|
CVE-2006-7134
|
2017-07-29 10:29 |
2007-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266519
|
- |
|
noah_spurrier
|
upload_tool_for_php
|
Successful exploitation requires valid user credentials.
|
NVD-CWE-Other
|
CVE-2006-7134
|
2017-07-29 10:29 |
2007-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266520
|
- |
|
php_poll_creator
|
php_poll_creator
|
PHP remote file inclusion vulnerability in lib/functions.inc.php in PHP Poll Creator (phpPC) 1.04 allows remote attackers to execute arbitrary PHP code via a URL in the relativer_pfad parameter, a di…
|
NVD-CWE-Other
|
CVE-2006-7135
|
2017-07-29 10:29 |
2007-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|